US10374803B2

Methods for internet communication security

Summary by NHIP

Hypervisor Packet Authorization

The product intercepts network packets within a hypervisor to decrypt higher-than-OSI layer three portions using single-use cryptographic keys. It authorizes traffic by comparing extracted parameters against expected values before passing packets to virtual devices after confirming secure pathway negotiations.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

The present disclosure relates to network security software cooperatively configured on plural nodes to authenticate and authorize devices, applications, users, and data protocol in network communications by exchanging nonpublic identification codes, application identifiers, and data type identifiers via pre-established communication pathways and comparing against pre-established values to provide authorized communication and prevent compromised nodes from spreading malware to other nodes.

US10374803B2, drawing sheet 1
Sheet 1 of 46

Term

11.5 yearsleft in the term

Expires 10 April 2038.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

24 claims: 1 independent, 23 dependent

  1. 1
    Broadest claimClaim Score 48, average(NHIP)A product for authorizing network communications in a hypervisor, the product comprising a non-transitory computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code executable in a hypervisor to perform communication management operations, the communication management operations comprising:i) intercepting a first network packet in the hypervisor, the first network packet comprising a first higher-than-OSI layer three portion;ii) decrypting, with a single-use cryptographic key, at least a portion of the first higher-than-OSI layer three portion to obtain one or more first packet parameters;iii) authorizing the first network packet in the hypervisor, comprising: comparing the one or more first packet parameters with one or more first expected values;and iv) passing the authorized first network packet to a virtual device.